SmartTubeÒòÊðÃûÃÜԿй¶Ôâ¶ñÒâ¸üÐÂÈëÇÖ

Ðû²¼Ê±¼ä 2025-12-03

1. SmartTubeÒòÊðÃûÃÜԿй¶Ôâ¶ñÒâ¸üÐÂÈëÇÖ


12ÔÂ1ÈÕ £¬¹ãÊܽӴýµÄAndroid TV¿ªÔ´YouTube¿Í»§¶ËSmartTubeÒò¿ª·¢ÕßYuriy YuliskovµÄÊðÃûÃÜԿй¶ £¬µ¼Ö¶ñÒâ¸üб»ÍÆË͸øÓû§ £¬Òý·¢Ç徲Σ»ú¡£¸ÃÓ¦ÓÃÒòÃâ·Ñ¡¢ÎÞ¹ã¸æ¼°ÔÚµÍÐÔÄÜ×°±¸ÉÏÁ÷ͨÔËÐеÄÌØµã £¬³ÉΪAndroid TV¡¢Fire TV StickµÈ×°±¸ÉÏÏÂÔØÁ¿×î¸ßµÄµÚÈý·½YouTube¿Í»§¶ËÖ®Ò»¡£ÊÂÎñÆØ¹âʼÓÚ¶àÃûÓû§±¨¸æ³Æ×°±¸ÄÚÖõÄPlay Protect·À²¡¶¾Ä£¿é×èÖ¹SmartTubeÔËÐв¢ÖÒÑÔΣº¦¡£YuliskovÈÏ¿ÉÆäÊý×ÖÃÜÔ¿ÔÚÉÏÖÜÍíЩʱ¼äÔâй¶ £¬¶ñÒâÈí¼þ±»×¢ÈëÓ¦Óá£ÄæÏò¹¤³ÌÏÔʾ £¬ÊÜѬȾµÄ30.51°æ±¾°üÀ¨Ò»¸öÃûΪlibalphasdk.soµÄÒþ²ØÍâµØ¿â £¬¸Ã¿â²»ÔÚ¹ûÕæÔ´´úÂëÖÐ £¬¿ÉÄÜΪ¶ñÒâÈí¼þ¡£¸Ã¿â¾²Ä¬ÔËÐÐ £¬ÎÞÐèÓû§½»»¥¼´¿Éʶ±ð×°±¸¡¢×¢²áÔ¶³Ìºó¶Ë £¬²¢Í¨¹ý¼ÓÃÜͨµÀ°´ÆÚ·¢ËÍÖ¸±ê¼°ÎüÊÕÉèÖà £¬Óû§ºÁÎÞ²ì¾õ¡£Ö»¹ÜÎÞÖ±½ÓÖ¤¾ÝÅú×¢±£´æÕË»§±»µÁ»òDDoS½©Ê¬ÍøÂçÔ˶¯ £¬µ«Ç±ÔÚΣº¦¼«¸ß¡£ÎªÓ¦¶ÔΣ»ú £¬YuliskovÒÑ×÷·Ï¾ÉÊðÃû £¬ÍýÏëÐû²¼´øÓÐ×ÔÁ¦Ó¦ÓÃIDµÄа汾 £¬²¢ÔÊÐíа汾ÉÏÏßF-Droidºó½â¾öËùÓÐÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/smarttube-youtube-app-for-android-tv-breached-to-push-malicious-update/


2. ÐÂÐÍMaaS°²×¿¶ñÒâÈí¼þAlbiriox¼ÓËÙÍþв½ðÈÚ»ú¹¹


12ÔÂ2ÈÕ £¬½üÆÚ £¬2025Äê £¬Ò»ÖÖÃûΪAlbirioxµÄÐÂÐÍ¡°¶ñÒâÈí¼þ¼´·þÎñ£¨MaaS£©¡±°²×¿¶ñÒâÈí¼þÔÚ¶íÓïÍøÂç·¸·¨ÂÛ̳·ºÆð £¬Æäͨ¹ý×°±¸ÍêÈ«½ÓÊÜÓëʵʱڲƭ¹¦Ð§¶ÔÈ«Çò400Óà¸öÒøÐм°¼ÓÃÜÇ®±ÒÓ¦ÓÃ×é³ÉÍþв¡£¾ÝCleafyÍþвÇ鱨ÍŶӯÊÎö £¬¸Ã¶ñÒâÈí¼þÖ§³Ö×°±¸¶Ëڲƭ£¨ODF£© £¬¾ß±¸Ô¶³Ì¿ØÖÆ¡¢Æ¾Ö¤ÇÔÈ¡ÄÜÁ¦ £¬²¢ÓÚ2025Äê9Ô´Ó˽È˲âÊÔ°æ¹ý¶ÉÖÁ10ÔÂÍÆ³öµÄ¹ûÕæMaaSģʽ £¬¶©ÔÄÓöÈÓÉÿÔÂ650ÃÀÔªÕÇÖÁ720ÃÀÔª £¬ÔËÓªÕß»¹ÍÆÏú»ùÓÚVNCµÄ¸¨Öú¹¦Ð§Ä£¿éÒÔʵÏÖʵʱÆÁÄ»Èö²¥ÊäºÍ½»»¥¡£ÔçÆÚ¹¥»÷ͨ¹ý¶ÌÐÅÁ´½Ó¶¨Ïò°ÂµØÊ¹Óû§ £¬ÓÕµ¼Æä»á¼ûαÔìGoogle PlayÍøÕ¾ÏÂÔØ¡°Penny Market¡±¶ñÒâÓ¦ÓÃ×÷ΪͶ·ÅÆ÷ £¬×îÖÕ¼ÓÔØAlbiriox£»ºó¸ÄΪͨ¹ýWhatsApp·¢ËÍÁ´½Ó²¢¹ýÂ˰µØÀûºÅÂë¡£¸Ã¶ñÒâÈí¼þʹÓÃJSONPacker»ìÏý´úÂë £¬ÓÕʹÊܺ¦Õ߯ôÓá°×°ÖÃδ֪ӦÓá±È¨ÏÞºó £¬Í¨¹ýδ¼ÓÃÜTCPͨµÀÅþÁ¬ÏÂÁî·þÎñÆ÷²¢×¢²á×°±¸¡£ÆäÖ§³ÖºÚÆÁÌáÐÑ¡¢UI×Ô¶¯»¯¼°ÏµÍ³¸üÐÂαװ £¬ÇÒ¿ª·¢Õßͨ¹ý¼¯³ÉGolden Crypt¼ÓÃÜ·þÎñÈÆ¹ý¾²Ì¬É¨Ãè £¬Ç¿»¯¹æ±Ü¼ì²âÄÜÁ¦¡£


https://www.infosecurity-magazine.com/news/android-maas-malware-albiriox-dark/


3. ×ÅÃûÆ·ÅÆÔâCalendly´¹ÂÚÖÂÆóÒµÕË»§Ç徲Σº¦


12ÔÂ2ÈÕ £¬½üÆÚ £¬Ò»³¡Õë¶ÔÍŽáÀû»ª¡¢µÏÊ¿Äá¡¢ÍòÊ´│¡¢LVMH¡¢UberµÈ×ÅÃûÆ·ÅÆµÄÍøÂç´¹ÂÚÔ˶¯Òý·¢¹Ø×¢¡£¹¥»÷ÕßÒÔCalendlyÈճ̰²ÅÅÆ½Ì¨ÎªÓÕ¶ü £¬Í¨¹ýÈ«ÐÄÉè¼ÆµÄÐéα¾Û»áÔ¼Çë £¬ÇÔÈ¡Google WorkspaceºÍFacebookÆóÒµÕË»§Æ¾Ö¤ £¬½ø¶øÌᳫ¶ñÒâ¹ã¸æÔ˶¯»òתÊÛÕË»§Ä²Àû¡£¸ÃÔ˶¯¾ßÓи߶ÈÕë¶ÔÐÔ £¬¹¥»÷Õßð³äÆ·ÅÆÕÐÆ¸Ö°Ô± £¬Ê¹ÓÃAI¹¤¾ßαÔ쳬75¸öÆ·ÅÆµÄÐéαÉí·Ý £¬ÏòÄ¿µÄ·¢ËͰüÀ¨¶ñÒâÁ´½ÓµÄ¾Û»áÔ¼Çë¡£Êܺ¦Õßµã»÷Á´½Óºó £¬»á±»Ö¸µ¼ÖÁαÔìµÄCalendlyµÇÂ¼Ò³Ãæ £¬¸ÃÒ³ÃæÏÈÏÔʾÑéÖ¤Âë £¬ÔÙÌø×ªÖÁAiTM£¨ÖÐÐÄÈ˹¥»÷£©´¹ÂÚÒ³Ãæ £¬ÊÔͼÇÔÈ¡Google WorkspaceµÇ¼»á»°¡£²¿·Ö±äÖÖ¹¥»÷»¹Ê¹ÓÃä¯ÀÀÆ÷ÄÚä¯ÀÀÆ÷£¨BitB£©ÊÖÒÕ £¬Í¨¹ýÏÔʾÕýµ±URLµÄÐéαµ¯³ö´°¿Ú £¬½øÒ»²½ÈƹýÓû§Ð¡ÐÄ¡£ÖµµÃ×¢ÖØµÄÊÇ £¬¹ã¸æÆ½Ì¨ÔÊÐíµØÀíλÖá¢ÓòÃû¼°×°±¸¶¨Ïò £¬Ê¹¹¥»÷Õ߿ɿªÕ¹¡°Ë®¿Óʽ¡±¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/fake-calendly-invites-spoof-top-brands-to-hijack-ad-manager-accounts/


4. ÒÁÀÊMuddyWater½ḛ̀³ÔÉßÌØ¹¤Èí¼þ¹¥»÷Öж«»ù½¨


12ÔÂ3ÈÕ £¬ÓëÒÁÀÊÇ鱨Óë¹ú¼ÒÇå¾²²¿±£´æ¹ØÁªµÄÍþвÐÐΪÌåMuddyWater £¬Õë¶Ô°£¼°ºÍÒÔÉ«ÁеÄÒªº¦»ù´¡ÉèÊ©ÌᳫÁËÒ»³¡ÊÖÒÕϸÃܵÄÍøÂç¹¥»÷¡£¸ÃÐж¯±¬·¢ÓÚ2024Äê9ÔÂÖÁ2025Äê3Ô £¬ÒÔÓã²æÊ½´¹ÂÚÓʼþΪ³õÊ¼ÔØÌå £¬Óʼþ¸½¼þαװ³ÉÕýµ±PDFÎĵµ £¬ÓÕµ¼Ä¿µÄµã»÷Á´½ÓÏÂÔØÍйÜÔÚOneHub¡¢MegaµÈÃâ·ÑÎļþ¹²ÏíÆ½Ì¨ÉϵÄÌØ¹¤Èí¼þ×°ÖóÌÐò¡£´Ë´Î¹¥»÷µÄ½¹µã¹¤¾ßΪÃûΪ"MuddyViper"µÄÐÂÐͺóÃųÌÐò £¬Æä¾ß±¸¶àÖØ¶ñÒ⹦Ч£º¿ÉÇÔÈ¡WindowsϵͳµÇ¼ƾ֤¡¢ä¯ÀÀÆ÷ÀúÊ·¼Í¼ÓëÃô¸ÐÊý¾Ý £¬ÍøÂçÖ÷»úÉèÖÃÐÅÏ¢ £¬Ô¶³Ì´«Êä»òÖ´ÐÐÎļþ £¬ÒÔ¼°Ö´ÐÐí§ÒâShellÏÂÁΪ¹æ±ÜÇå¾²¼ì²â £¬MuddyViper½ÓÄÉÁËÃûΪ"Fooder"µÄ×Ô½ç˵¼ÓÔØÆ÷ £¬¸Ã¼ÓÔØÆ÷ͨ¹ýÄ£Äâ¾­µäÓÎÏ·"̰³ÔÉß"µÄÔËÐÐÂß¼­ÊµÏÖÒþ²Ø¼ÓÔØ £¬ÆäʹÓÃ̰³ÔÉßµÄ"½¹µãÂß¼­"ÓëWindows Sleep APIŲÓù¹½¨ÑÓ³Ùº¯Êý £¬½«¶ñÒâ´úÂë·´Éä¼ÓÔØÖÁÄÚ´æÖ´ÐÐ £¬ÓÐÓÃÑÓ»º¶ñÒâÐÐΪ̻¶ʱ¼ä £¬¶Ô¿¹×Ô¶¯»¯ÆÊÎöϵͳ¡£


https://therecord.media/iran-linked-hackers-target-israel-egypt-phishing


5. È«ÇòChatGPT·þÎñÍ»·¢¹ÊÕÏ £¬OpenAI½ôÆÈÐÞ¸´ÖÐ


12ÔÂ2ÈÕ £¬OpenAIÆìÏÂAI̸Ì칤¾ßChatGPTÔÚÈ«Çò¹æÄ£ÄÚÍ»·¢´ó¹æÄ£¹ÊÕÏ £¬Óû§»á¼ûʱƵÈÔÊÕµ½"ËÆºõ³öÁ˵ãÎÊÌâ""ÌìÉúÏìӦʱÍÉ»¯"µÈ¹ýʧÌáÐÑ¡£¾ÝÓû§·´Ïì¼°²âÊÔÏÔʾ £¬¹ÊÕÏÌåÏÖΪ̸Ìì½çÃæÒ»Á¬¼ÓÔØÎÞÏìÓ¦¡¢ÀúÊ·¶Ô»°ÄªÃûÏûÊÅ¡¢ÐÂÐÂÎÅ·¢Ëͺó³¤Ê±¼ä¿¨¶ÙµÈÎÊÌâ¡£DownDetectorʵʱ¼à²âÊý¾ÝÏÔʾ £¬¹ÊÕÏá¯ÁëÆÚÈ«Çò³¬3ÍòÃûÓû§±¨¸æ·þÎñÒì³£ £¬ÆäÖÐÃÀ¹ú¶«²¿µØÇøÓû§ÊÜÓ°Ïì×îΪÏÔÖø¡£OpenAI¹Ù·½ÓÚÃÀ¹ú¶«²¿Ê±¼ä2:40Ðû²¼ÉùÃ÷ £¬ÈÏ¿ÉÒÑ×¢ÖØµ½ChatGPT·þÎñÒì³£ÎÊÌâ £¬²¢ÕýÈ«Á¦ÅŲéÐÞ¸´¡£¹«Ë¾Í¸Â¶ £¬¹ÊÕϱ¬·¢ºó¹ýʧÂÊÏÔÖøÉÏÉý £¬ÊÜÓ°ÏìÓû§ÆÕ±éÔâÓö·þÎñÖÐÖ¹»òÐÔÄÜϽµ¡£ÊÖÒÕÍŶӯðÔ´ÅŲ鷢Ã÷ £¬´Ë´Î¹ÊÕÏÉæ¼°¶àÇøÓò·þÎñÆ÷¼¯Èº £¬¿ÉÄÜÔ´Óڵײã¼Ü¹¹¸ºÔعý¸ß»òÔÝʱÐÔϵͳ¹ýʧ¡£×èÖ¹ÃÀ¹ú¶«²¿Ê±¼ä15:14 £¬OpenAI¸üÐÂÏ£Íû³ÆChatGPT·þÎñÒÑ×îÏÈÖð²½»Ö¸´ £¬µ«ÕûÌåÏìÓ¦ËÙÂÊÈÔ½ÏÂý £¬²¿·Ö¹¦Ð§ÉÐδÍêÈ«Õý³£¡£¹«Ë¾Ç¿µ÷ £¬½«¼ÌÐøÓÅÏÈ´¦Öóͷ£Óû§ÅþÁ¬ÎÊÌâ £¬²¢ÍýÏëÔÚÍêÈ«ÐÞ¸´ºóÐû²¼Ïêϸ¹ÊÕÏÆÊÎö±¨¸æ¡£


https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-is-down-worldwide-conversations-dissapeared-for-users/


6. Ë÷°î´óѧÔâÓö´ó¹æÄ£Ô±¹¤Êý¾Ýй¶


12ÔÂ1ÈÕ £¬·¨¹ú¶¥¼âѧ¸®Ë÷°î´óѧ¿ËÈÕ¾íÈëÖØ´óÊý¾Ýй¶ÊÂÎñ £¬ºÚ¿ÍÔÚ°µÍø²»·¨ÂÛ̳Ðû³ÆÇÔÈ¡Á˰üÀ¨3.2ÍòÌõÔ±¹¤ÐÅÏ¢µÄÃô¸ÐÊý¾Ý £¬Éæ¼°ÒøÐÐÕ˺š¢ÈËΪ¼Í¼¡¢Éí·ÝÖ¤¼þµÈ¶àÀàÒþ˽ÄÚÈÝ¡£´Ë´ÎÊÂÎñÓÉÍþвÇ鱨»ú¹¹Daily Dark WebÊ×´ÎÅû¶ £¬ËæºóCybernewsÑо¿Ö°Ô±¶ÔÑù±¾Îļþ¾ÙÐÐºË²é £¬·¢Ã÷Êý¾Ý°üÀ¨È«Ãû¡¢²¿·Ö¡¢Ö°Î»¡¢ÓÊÏä¡¢ÌõÔ¼ÀàÐÍ¡¢Ð½×Ê¡¢ÄÚ²¿Ô±¹¤´úÂë¼°¿ÉÄܱ£´æµÄÓÊÕþ±àÂëµÈÏêϸ×Ö¶Î £¬µ«Î´°üÀ¨ÆäËûÍþвÐÐΪÕßÉù³ÆµÄÍêÕûÊý¾Ý¼¯¡£¾ÝºÚ¿ÍÔÚÂÛ̳µÄÉùÃ÷ £¬Ð¹Â¶Êý¾Ýº­¸ÇÆß´óÀàÐÅÏ¢£º×¨ÒµÉí·ÝÐÅÏ¢£¨ÈçÄÚ²¿±êʶ·û¡¢¾Íҵ״̬£©¡¢ÌõÔ¼Êý¾Ý£¨ÆðÖ¹ÈÕÆÚ¡¢ÐÐÕþÎļþPDF£©¡¢Ð½³ê¼Í¼£¨½±½ð½òÌù¡¢µç×ÓÈËΪµ¥£©¡¢ÒøÐÐÐÅÏ¢£¨RIB/IBAN¡¢BICÕ˺ţ©¡¢Éç»á°ü¹ÜÐÅÏ¢£¨Éç±£ºÅÂë¡¢²¡¼Ù֤ʵ£©¡¢¸¨ÖúÎļþ£¨¼òÀú¡¢½áÒµÖ¤Ê飩¼°ÆäËûÈËÁ¦×ÊÔ´µ¼³öÊý¾Ý£¨Ô±¹¤±í¡¢Ê¹Ãü·ÖÅɱíµÈ£©¡£


https://cybernews.com/security/sorbonne-universite-data-security-incident/